Git Product home page Git Product logo

Comments (10)

damassi avatar damassi commented on June 12, 2024 2

@kajatiger - love the idea of a dep rotation; looking at force for example, or Palette, or any of our other web areas its clear things are very much out of date in places. Having a rotation like that would also help devs get more involved with the tooling aspect of our codebases.

However! That part of this RFC should be a separate RFC just because its a significant process switch, and in regards to DepFu, there's a lot to talk about as we already have some competing dep managers in place.

Do you think you could break this into two RFCs?

from readme.

icirellik avatar icirellik commented on June 12, 2024 2

A lot of progress has been made to better surface the security information from Dependabot.

This Looker dashboard lists all the vulnerabilities by team and repository: link 🔒

This Notion document describes how we are using Dependabot: link 🔒

from readme.

dzucconi avatar dzucconi commented on June 12, 2024 1

Love the idea of a rotation and have heard good things about depfu.

from readme.

damassi avatar damassi commented on June 12, 2024 1

Does it cover languages other than Ruby?

If this RFC is accepted it might be good to outline a full migration path in the resolution section, and loop in some repo maintainers to help things along.

from readme.

kajatiger avatar kajatiger commented on June 12, 2024 1

Depfu covers all Ruby, JS and Elixir projects.

from readme.

joeyAghion avatar joeyAghion commented on June 12, 2024 1

Can you clarify how you mean that Dependabot's not configurable? It seems similar in most respects.

I'm not married to Dependabot, but do see a lot of value in being consistent across repositories. I wouldn't want something as foundational as dependency management to vary without good reasons.

from readme.

kajatiger avatar kajatiger commented on June 12, 2024

Okay @damassi thanks for your suggestion. I split the RFCs in two now and it does make more sense to discuss things separately.

from readme.

pvinis avatar pvinis commented on June 12, 2024

Since renovate (in the repos it is active on) works, but I agree it can be hard to configure, I'd like to try depfu and see how it feels as well.
Eigen has renovate with a bunch of stuff disabled, which is not helping. I could add depfu on echo, which is much smaller, and help compare too. 🤔

from readme.

mdole avatar mdole commented on June 12, 2024

Cool! Definitely like the idea of having consistent, easy-to-understand dependency updates for all of Artsy's repos.

Something I think this RFC should cover: how much would Depfu cost for Artsy? And how much work would it take to set up and maintain?

from readme.

kajatiger avatar kajatiger commented on June 12, 2024

Thank you @icirellik ! I still find the dependabot config a bit counter intuitive and also from our configurations now it is conflicting with the other RFC about a rotating depency update routine. But I guess this can be discussed individually on a team level and repo level.
In order to gain some insight on how to configure dependabot there are documentations here: https://docs.github.com/en/code-security/supply-chain-security/keeping-your-dependencies-updated-automatically/customizing-dependency-updates

So sadly closing this RFC now.

Resolution

We decided to leave things as they are.

Level of Support

5: Unclear Resolution.

Additional Context:

Some people were in favor of it, but some people did not see the benefits of the change.

Next Steps

We will stick to dependabot.

Exceptions

None

from readme.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.